Trust & Compliance

HIPAA, Security & Business Associate Agreements

Esoteric Sync handles protected health information (PHI). We designed for that reality from the first line of code — not as an afterthought. This page explains how.

Last updated: July 2026

Our security posture, in plain language

Esoteric Sync was built by a working skilled nursing facility nurse — which means it was built by someone whose own license sits behind every note. We treat PHI the way a nurse treats a med cart: locked by default, accessed only with a reason, and accounted for at every step.

Encryption

Encrypted in transit and at rest

All data moving between your device and our systems is encrypted in transit (TLS), and stored data is encrypted at rest.

Data Minimization

We keep the minimum, for the minimum time

Voice recordings and draft content are retained only as long as needed to produce your documentation, then purged on a defined retention schedule.

Access Control

Least-privilege access

Access to production systems is restricted, role-based, and limited to the minimum necessary to operate and support the service.

Human in the Loop

The nurse controls the record

Sync never writes to a medical record on its own. Every output is reviewed and approved by a licensed nurse before it goes anywhere.

HIPAA and our role

When Esoteric Sync is deployed by a skilled nursing facility or its operating company, Esoteric Healthcare Systems LLC acts as a business associate as defined under the Health Insurance Portability and Accountability Act (HIPAA) and its implementing regulations, including the Privacy Rule, Security Rule, and Breach Notification Rule.

As a business associate, we:

  • Use and disclose PHI only as permitted by our Business Associate Agreement (BAA) with the covered entity and as required by law;
  • Implement administrative, physical, and technical safeguards designed to protect the confidentiality, integrity, and availability of electronic PHI;
  • Apply the minimum necessary standard to uses and disclosures of PHI;
  • Report security incidents and breaches of unsecured PHI to the covered entity as required by the Breach Notification Rule and the terms of our BAA;
  • Ensure that subcontractors who create, receive, maintain, or transmit PHI on our behalf agree to equivalent protections through written agreements;
  • Make PHI available as required to satisfy a covered entity's obligations regarding individual access and accounting of disclosures.

Business Associate Agreements

We sign BAAs with every facility customer. No exceptions. A signed BAA is a condition of deployment — we will not process PHI for a covered entity without one in place.

Our standard BAA covers permitted uses and disclosures, safeguard obligations, breach notification timelines, subcontractor flow-down requirements, and termination-and-return/destruction of PHI. We're glad to work from our standard agreement or review yours.

For DONs and administrators: if your corporate office or compliance team needs our BAA, security documentation, or answers to a vendor security questionnaire, email us at hello@esotericsync.com and we'll turn it around promptly.

Technical safeguards

Infrastructure

Esoteric Sync runs on established cloud infrastructure providers with independently audited security programs. We maintain written agreements, including BAAs or equivalent data protection terms, with subprocessors that handle PHI on our behalf. A current list of subprocessors is available on request.

AI processing

Voice transcription and documentation structuring are performed by third-party AI providers operating under appropriate data protection agreements. Your data is not used to train third-party AI models. AI processing is transient: inputs are processed to generate your documentation and are not retained by Esoteric Sync beyond our defined retention window.

Retention and deletion

Voice recordings and generated drafts are retained only for the period necessary to deliver the service, after which they are automatically deleted. Facility customers may request specific retention configurations as part of onboarding.

Audit and monitoring

We log access to production systems and monitor for anomalous activity. Logs supporting security investigations are retained in accordance with our internal security policies.

What Esoteric Sync deliberately does not do

  • No autonomous charting. Sync never files, signs, or submits documentation. The licensed nurse reviews and approves every word before it enters the record.
  • No fabricated clinical data. Measured values (vitals, doses, lab results) are never inferred or invented. Anything unconfirmed is flagged for the nurse to complete — not filled in.
  • No selling of data. We do not sell PHI or personal information. Ever.
  • No training on your residents. PHI processed through Sync is not used to train AI models.

Incident response

We maintain an incident response process covering identification, containment, investigation, and notification. In the event of a breach of unsecured PHI, we notify affected covered entities without unreasonable delay and within the timelines required by the Breach Notification Rule and our BAA, and we cooperate fully with the covered entity's own notification obligations.

Questions, requests, and reporting

Security researchers, facility compliance teams, and customers can reach us directly. If you believe you've identified a vulnerability in Esoteric Sync, please report it to us before public disclosure and we will respond promptly.

Security & compliance contact

BAA requests, security questionnaires, subprocessor lists, vulnerability reports, and anything else on this page.